CVE-2025-55737

MEDIUM

flaskBlog <2.8.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every user can delete an arbitrary comment of another user on every post, by simply intercepting the delete request and changing the commentID. The code that causes the problem is in routes/post.py.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0008
EPSS Percentile 24.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
dogukanurker/flaskblog < 2.8.0
Published Aug 19, 2025
Tracked Since Feb 18, 2026